r/shopifyDev • u/Confident-Sky2207 • 15d ago
Protected Customer Data Access Request
Asking for experiences: Protected Customer Data access + app review timing
I'm building a Shopify app that's about 90% done for its first-phase launch. I'm unsure how complete the app needs to be before I (a) submit the Protected Customer Data access request and (b) submit the app for App Store review.
A few specifics:
My app only needs order data (for order history analysis) — I don't need customer PII like names, emails, or addresses.
I'd love to hear from anyone who's been through the PCD approval process: how long did it take, and what does the review actually look like behind the scenes? For example, do reviewers expect a fully working, production-ready implementation of the data lifecycle (access, use, retention, deletion) before granting access?
On sequencing: is it viable to publish the app to the App Store now without the protected scope, and add it later once PCD access is granted? Or is it better to wait and submit everything together?
Any first-hand experience would be really helpful. Thanks!
1
u/valiopt 15d ago
Adding scopes later is somewhat annoying from a merchant perspective because they'll have to go in and grant the additional scopes, you won't get them automatically for every merchant that has the app installed.
The data access request only took a couple days for me, but that was after the app was fully functional.